1Password records every time you unlock your vault, create an item, or complete onboarding. If you're on a business plan, your employer's IT admin decides whether this happens — you can't turn it off yourself. Moving to Electron means 1Password inherits every Chrome vulnerability. CVE-2024-42219 let malware on your Mac steal vault items through a process communication flaw. Your password manager has the same attack surface as a web browser.
What they claim: 1Password uses AES-256-GCM with 650,000 PBKDF2 iterations plus a 128-bit Secret Key
What we found: CVE-2024-42219 (critical): macOS inter-process communication bypass allowed local malware to exfiltrate vault items. CVE-2024-42218 (high): macOS outdated version bypass. CVE-2023-4863 (critical): inherited libwebp heap buffer overflow from Electron framework. The move to Electron introduced an entire browser attack surface into a password manager.
What they claim: 1Password privacy policy states telemetry is 'optional' and can be disabled
What we found: For personal/family accounts telemetry is opt-in. But for Teams and Business accounts (where the most sensitive corporate credentials are stored), telemetry is enabled by default and individual team members cannot opt out — only account owners can. The people with the least control over their data are in the most sensitive environments.
What they claim: 1Password has never suffered a data breach and maintains strong audit certifications
What we found: 1Password holds SOC 2 Type 2, ISO 27001:2022, and multiple ISO certifications. However, the October 2023 Okta incident exposed 1Password's internal systems to an attacker who accessed an IT team member's HAR file. While no user data was compromised, the incident demonstrated supply-chain risk through identity providers.
What they claim: 1Password states 'we can never see your passwords' and operates zero-knowledge architecture
What we found: Telemetry endpoint telemetry.1passwordservices.com collects event data including timestamps of every unlock, vault access, and item interaction. While vault contents aren't transmitted, the behavioral metadata reveals when users access passwords, how often, and from which devices — a detailed usage fingerprint.
What they claim: 1Password markets itself as a privacy-first product — 'your data is your data'
What we found: 1Password added telemetry in 2023 that collects usage data including unlock events, item creation, onboarding completion, device type, and account metadata. For business accounts, telemetry is ON by default and individual employees cannot opt out — only account owners can disable it.
What they claim: 1Password uses crash reporting via in.appcenter.ms (Microsoft App Center)
What we found: Crash reports can contain memory dumps with potentially sensitive data. The app also connects to multiple analytics endpoints. For a product whose entire value proposition is keeping secrets, any outbound data transmission is a potential attack surface.